Web Hack List

Top 10 winner

Exploiting XXE in File Upload Functionality

Shows how XXE can reach uploaded OOXML documents and XMP metadata in PDFs and image formats. Covers the oxml_xxe tool, document-part parsing, a Java XMP parser example, and testing for entity expansion, XSS, file access and SSRF. Emphasizes that upload parsers may differ from API parsers and require separate configuration checks.

Record

Researcher
Will Vandevanter
Published by
Black Hat
Format
Recording
Topic
Injection

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Will Vandevanter, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .